Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Opinion

Most Commented Content posted in February 2016
Security Lessons From My Doctor
Commentary  |  2/25/2016  | 
Why its hard to change risky habits like weak passwords and heavy smoking, even when advice is clear.
Security Lessons From My Car Mechanic
Commentary  |  2/18/2016  | 
What an unlocked oil pan taught me about me about the power of two-way communication between security pros and the organizations they serve.
Name That Toon: Dark Reading Caption Contest
Commentary  |  2/13/2016  | 
Take part in our brand new cartoon caption contest. Join the fun and maybe you'll win a prize.
Cybersecurity Smackdown: What Side Are You On?
Commentary  |  2/4/2016  | 
Analytics vs. Encryption. Prevention vs. Detection. Machine Learning: Promise or Hype? The Firewall: Dead or Still Breathing? The sharpest minds in the security industry debate some of the industry's most contentious issues.
Cybersecurity & Healthcare: Does Cybersecurity Act Help or Hurt?
Commentary  |  2/12/2016  | 
Without adequate resources, the new Cybersecurity Act of 2015 Act is merely a snapshot in time that does little to safeguard sensitive medical information.
The ROI Of Infosec: 11 Dos and Donts For Management Buy In
Commentary  |  2/27/2016  | 
The case for a bigger bottom line depends on how well you argue that the business cant run without a specific level of security infrastructure.
Modern Web Apps: Not The Risk They Used To Be (Theyre Worse!)
Commentary  |  2/26/2016  | 
Even a tiny Web application without a single byte of confidential data can expose your corporate crown jewels to cybercriminals.
Simplifying Application Security: 4 Steps
Commentary  |  2/10/2016  | 
It's time to leave behind the misconceptions about the cost and effort required by effective application security. Here's how.
Public Vs. Private: Is A Prestigious Infosec College Degree Worth It?
Commentary  |  2/24/2016  | 
Today's graduates coming into the information security industry from private universities arent ready for the workforce.
Encryption Has Its Place But It Isnt Foolproof
Commentary  |  2/2/2016  | 
Most encrypted data is unencrypted at some point in its lifecycle -- and the bad guys are pretty good at finding the one window left open.
New Kid On The Block: Cyber Threat Analyst
Commentary  |  2/4/2016  | 
Drawing from the financial service industry, this new role uses the art of the intelligence cycle to drive efficiency in the security operations center.
Monday Morning Quarterbacking Super Bowl 50: Infosec Edition
Commentary  |  2/8/2016  | 
How to coach your team to victory in the battle to protect corporate data and intellectual property. After all, theres a lot riding on your game, too.
Today's New Payment Card Security In A Nutshell
Commentary  |  2/17/2016  | 
Businesses taking their time rolling out EMV card-compatible terminals are putting their data security and financial well-being at risk.
A Proactive Approach To Incident Response: 7 Benefits
Commentary  |  2/22/2016  | 
How implementing a digital forensic readiness program maximizes the value of digital evidence.
3 Flavors of Machine Learning: Who, What & Where
Commentary  |  2/11/2016  | 
To get beyond the jargon of ML, you have to consider who (or what) performs the actual work of detecting advanced attacks: vendor, product or end-user.
Anatomy Of An Account Takeover Attack
Commentary  |  2/23/2016  | 
How organized crime rings are amassing bot armies for password-cracking attacks on personal accounts in retail, financial, gaming, and other consumer-facing services.
Measuring Security: My Dwell Time Obsession
Commentary  |  2/29/2016  | 
How I discovered the critical metric to fuel my drive to create the most secure environment possible.


Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-20001
PUBLISHED: 2020-08-04
An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges.
CVE-2020-15467
PUBLISHED: 2020-08-04
The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise.
CVE-2020-5615
PUBLISHED: 2020-08-04
Cross-site request forgery (CSRF) vulnerability in [Calendar01] free edition ver1.0.0 and [Calendar02] free edition ver1.0.0 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
CVE-2020-5616
PUBLISHED: 2020-08-04
[Calendar01], [Calendar02], [PKOBO-News01], [PKOBO-vote01], [Telop01], [Gallery01], [CalendarForm01], and [Link01] [Calendar01] free edition ver1.0.0, [Calendar02] free edition ver1.0.0, [PKOBO-News01] free edition ver1.0.3 and earlier, [PKOBO-vote01] free edition ver1.0.1 and earlier, [Telop01] fre...
CVE-2020-5617
PUBLISHED: 2020-08-04
Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors.